Hi,
I wanted to know what is the best technique used for creating fields for multiple sourcetypes.
For example if i have 4 sourcetype named
st1,st2,st3,st4
I want to extract a field which displays errros.
So shall I create duplicate fields for each sourcetype or there is some better method available.
Yes, you will have separate fields extractions for each sourcetype. If st1, st2 etc are all the same format then you'd combine them into a single sourcetype.
You could define an eventtype to have a nice way to search across all of those sourcetypes for specific errors.
http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Defineeventtypes